X / xAI Program Statistics


View program

45 total issues disclosed

$19,950 total paid publicly

Most disclosed (6 disclosures) — Improper Access Control - Generic



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
Cross-Domain Leakage of X Username / UserID due to Dynamically Generated JS File Information Disclosure th0h0 Medium 2024-05-10
Ability to see hidden likes Improper Access Control - Generic mirhat Medium 2024-05-10
Bypassing x profile verification to receive instant blue checkmark and unlimited profile changes Business Logic Errors itsdavid Low 2024-03-26
Able to see Twitter Circle tweets due to improper access control on the "FavoriteTweet" endpoint Improper Access Control - Generic bugra Medium 2024-03-01
Ability to getting Twitter Blue verified badge without purchase it Business Logic Errors alp Medium 2024-02-22
Improper santization of edit in list feature at twitter leads to delete any twitter user's list cover photo. Insecure Direct Object Reference (IDOR) greytesla Medium 2023-09-18
Twitter Subscriptions Information Disclosure Information Disclosure mirhat Medium 2023-09-18
The Deleted Polls is Still Accessable after 30 Days Privacy Violation eissen5c High 2023-02-13
Chained open redirects and use of Ideographic Full Stop defeat Twitter's approach to blocking links Security Through Obscurity jub0bs Medium 2022-12-29
Link-shortener bypass (regression on fix for #1032610) Security Through Obscurity jub0bs Medium 2022-12-12
Remote 0click exfiltration of Safari user's IP address Forced Browsing max2x Medium 2022-06-15
Identify the mobile number of a twitter user Information Disclosure aymen_mansour Critical 2022-03-29
Blind XSS on Twitter's internal Jira panel at ████ allows exfiltration of hackers reports and other sensitive data Cross-site Scripting (XSS) - Stored iambouali Critical 2022-02-12
Discoverability by phone number/email restriction bypass Improper Access Control - Generic zhirinovskiy High 2022-02-11
Subdomain takeover of images.crossinstall.com Business Logic Errors ian High 2022-01-05
PI leakage By Brute Forcing and Phone number deleting without using password Improper Access Control - Generic a13h1 Medium 2021-04-22
2 Subdomains Takeover at readfu.com Privilege Escalation m7mdharoun Medium 2021-03-15
Bypass Password Authentication to Update the Password Improper Authentication - Generic a13h1 Medium 2021-02-12
Bypass Password Authentication to Update the Password Improper Authentication - Generic a13h1 High 2021-01-11
iOS app crashed by specially crafted direct message reactions Uncontrolled Resource Consumption alexiaya Medium 2020-02-21
Stored XSS in https://app.mopub.com Cross-site Scripting (XSS) - Stored august1808 Medium 2019-12-17
[Twitter Open Source] Releases were & are built/executed/tested/released in the context of insecure/untrusted code Cryptographic Issues - Generic jlleitschuh High 2019-12-13
Access MoPub Reports Data even after Company removed you from their MoPub Account. Information Disclosure suyog High 2019-11-05
login csrf in analytics.mopub.com Cross-Site Request Forgery (CSRF) protostar0 Medium 2019-10-02
Reports Modal in app.mopub.com Disclose by any user Information Disclosure updatelap Medium 2019-10-02
Periscope-all Firebase database takeover Improper Access Control - Generic deeptiman Critical 2019-09-25
AppLovin API Key hardcoded in a Github repo Cleartext Storage of Sensitive Information hackbotone_ High 2019-09-18
Html Injection and Possible XSS via MathML Cross-site Scripting (XSS) - Generic z41b1337_ Critical 2019-09-03
Wrong Interpretation of URL encoded characters, showing different punny code leads to redirection on different domain Open Redirect mr_edwards Low 2019-08-26
cookie injection allow dos attack to periscope.tv Uncontrolled Resource Consumption protostar0 Medium 2019-07-03
Subdomain takeover on dev-admin.periscope.tv Privilege Escalation h1ch3ro Medium 2019-05-28
HTTPS is not validating TLS mac codes Use of a Broken or Risky Cryptographic Algorithm cy1337 No rating 2019-05-25
Protected Tweets setting overridden by Android app None supplied alexiaya Low 2019-05-17
Twitter lite(Android): Vulnerable to local file steal, Javascript injection, Open redirect Improper Access Control - Generic rahulkankrale Critical 2019-04-29
Protected tweets exposure through the URL Information Disclosure terjanq High 2019-04-19
Multiple XSS on account settings that can hijack any users in the company. Cross-site Scripting (XSS) - Stored giddsec Critical 2019-04-01
CSRF on https://www.niche.co leads to "account disconnection" Cross-Site Request Forgery (CSRF) mik317 Medium 2019-03-02
CSRF and probable account takeover on https://www.niche.co Cross-Site Request Forgery (CSRF) mik317 Medium 2019-02-28
Information Exposure Through Directory Listing vulnerability on 8 vcache**.usw2.snappytv.com websites Information Exposure Through Directory Listing ameerpornillos Low 2019-02-11
Tracking of users on third-party websites using the Twitter cookie, due to a flaw in authenticating image requests Privacy Violation cris-staicu Medium 2019-02-08
[dev.twitter.com] XSS and Open Redirect Protection Bypass None supplied bywalks Medium 2019-02-07
Incorrect details on OAuth permissions screen allows DMs to be read without permission Privacy Violation edent Medium 2018-12-14
Opportunity to post hidden comments Business Logic Errors csanuragjain Critical 2018-12-11
CORS misconfig | Account Takeover None supplied nahoragg High 2018-12-10
Global defaming of any twitter user Business Logic Errors csanuragjain Critical 2018-12-06